---
id: CVE-2026-90509
title: A weakness has been identified in dromara orion-visor up to 2.5.7
summary: >-
  A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by
  this issue is the function ExposeApiAspect.beforeExposeApi of the file
  ExposeApiAspect.java. Executing a manipulation can lead to hard-coded
  credentials. The …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-259
  - CWE-798
vendor: dromara
product: orion-visor
affected:
  - orion-visor 2.5.0
  - orion-visor 2.5.1
  - orion-visor 2.5.2
  - orion-visor 2.5.3
  - orion-visor 2.5.4
  - orion-visor 2.5.5
  - orion-visor 2.5.6
  - orion-visor 2.5.7
published: '2026-09-13'
updated: '2026-09-20'
sourceUpdated: '2026-09-20T01:16:32.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90509'
references:
  - url: 'https://github.com/dromara/orion-visor/'
    label: cna@vuldb.com
  - url: 'https://github.com/dromara/orion-visor/issues/170'
    label: cna@vuldb.com
  - url: >-
      https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/ExposeApi%20Hardcoded%20Default%20Token%20Authentication%20Bypass%20(CWE-798)_en.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90509'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911864'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403097'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403097/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-20T00:10:34.891101Z'
epss: 0.005
epssPercentile: 0.4024
ingestedAt: '2026-09-14T15:23:07.472Z'
---

## Overview

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
